# Problem using non-standard port

**URL:** <https://community.letsencrypt.org/t/problem-using-non-standard-port/78783>\
**Category:** Help\
**Created:** [November 29, 2018, 2:04pm UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783 "2018-11-29T14:04:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mn1247](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@mn1247](https://community.letsencrypt.org/u/mn1247)\
**Post date:** [November 29, 2018, 2:04pm UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/1 "2018-11-29T14:04:10Z")

</div>

I have a home webcam server that I want to access via https. Thus, I’m trying to set up a LetEncrypt certificate. My internet provider (Comcast) provides a non-static IP address and blocks port 443, so I have to use an alternate port and route through a DDNS service (Dynu).

I’m thinking I need to use certbot’s DNS verification to achieve this, and have executed the following command on my server…

sudo certbot certonly –manual –preferred-challenges dns

I specified [nelsamia.com](http://nelsamia.com) for the domain, and created a TXT record in the DNS with the text…

\_acme-challenge.nelsamia.com=m17HqrYSurdnIYxxxxxxxxxxxxxxxxxxx

I get an error saying “No TXT record found at \_acme-challenge.nelsamia.com”

Where am I going wrong?  
Thanks  
Eric

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [November 29, 2018, 3:12pm UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/2 "2018-11-29T15:12:40Z")

</div>

Hi @mn1247

if you use dns-challenge, the port is irrelevant.

> [@mn1247](#):
>
> \_acme-challenge.nelsamia.com=m17HqrYSurdnIYxxxxxxxxxxxxxxxxxxx
> 
> I get an error saying “No TXT record found at \_acme-challenge.nelsamia.com”

I can't find a dns txt entry. Did you create one with the name

```nohighlight
_acme-challenge.nelsamia.com

```

and the value `m17HqrYSurdnIYxxxxxxxxxxxxxxxxxxx`?

Or did you create one with the name `_acme-challenge.nelsamia.com=m17HqrYSurdnIYxxxxxxxxxxxxxxxxxxx` without a value?

Perhaps share a screenshot of your dns menu.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [November 29, 2018, 3:37pm UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/3 "2018-11-29T15:37:02Z")

</div>

Now I see the problem.

> D:\temp\>nslookup -type=txt [nelsamia.com](http://nelsamia.com).  
> [nelsamia.com](http://nelsamia.com) text =
> 
> ```
> "_acme-challenge.nelsamia.com=m17HqrYSurdnIYYOR4IC3n7xZyAi61hPNoOi2zehGVY"
> 
> ```

You have created a new txt entry with the name `nelsamia.com` and the wrong content.

The name must be

```nohighlight
_acme-challenge.nelsamia.com

```

and the content must be

```nohighlight
m17HqrYSurdnIYYOR4IC3n7xZyAi61hPNoOi2zehGVY

```

The content will change if you try it again.

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [November 29, 2018, 3:44pm UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/4 "2018-11-29T15:44:29Z")

</div>

Hi @mn1247,

As @JuergenAuer said, you have created the wrong TXT record, as you are using dynu, your TXT record should look like this:

 ![imagen](https://global.discourse-cdn.com/letsencrypt/original/3X/b/e/befeb61d9b01bbade47b6da48346532b8d2f2232.png)

Keep in mind that if the validation already failed, then this token `m17HqrYSurdnIYYOR4IC3n7xZyAi61hPNoOi2zehGVY` won’t be valid and you should execute the certbot command again, take the new token and update the TXT record on dynu.

Good luck,  
sahsanu

---

<div class="post-metadata">

**Author:** ![mn1247](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@mn1247](https://community.letsencrypt.org/u/mn1247)\
**Post date:** [December 1, 2018, 4:15am UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/5 "2018-12-01T04:15:09Z")

</div>

That solved it! Thanks so much for all the help.

One follow-up question if I may… how do I auto-renew the certificate? If I type

```auto
sudo certbot renew --dry-run

```

I just get errors about not having an authentication script. Is there an example of how to do this?  
Thanks again  
Eric

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [December 1, 2018, 4:40am UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/6 "2018-12-01T04:40:49Z")

</div>

> [@mn1247](#):
>
> how do I auto-renew

You cannot auto-renew when using `--manual`.

Consider using acme.sh, which supports automatically renewing via Dynu's DNS API.

(If you want to keep using Certbot, you can write your own script to talk to the Dynu API and perform the DNS update - [User Guide — Certbot 2.7.0.dev0 documentation](https://certbot.eff.org/docs/using.html#pre-and-post-validation-hooks))

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [December 1, 2018, 5:15am UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/7 "2018-12-01T05:15:19Z")

</div>

Hi,

> [@mn1247](#):
>
> My internet provider (Comcast) provides a non-static IP address and blocks port 443

I'm also a Comcast Xfinity user.

Comcast does not block any incoming http / https ports, I believe they blocked outgoing connections to SMTP ports. (And there might be other ports that are blocked, I haven't discovered any yet)

If your http and https ports are blocked, you might want to contact Comcast customer service to sort this out...

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 31, 2018, 5:15am UTC](https://community.letsencrypt.org/t/problem-using-non-standard-port/78783/8 "2018-12-31T05:15:26Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
